Documentation / Query & analyse
What tends to follow?
See what happened next during an incident, and how quickly.
What tends to follow? shows, for an incident, what happened next: which event followed which in the incident’s timeline, and how quickly. Use it to see how an incident unfolded and which early signs came before the errors.
Using it
- Open an incident and select the What tends to follow? tab. You can also reach it from a service’s page in Services, which lists that service’s incidents.
- Read the list from the top. Each entry shows one event in the timeline and the event that followed it, with the time between them. The closest-following pairs come first.
- If the tab says there is not enough timeline, the incident does not yet have enough events to show what followed what.
Things to keep in mind
- Order is not cause. One event following another does not prove that the first caused the second. Confirm anything important with Search or SQL.
- Combine it with What changed? to see which log patterns moved during the same period.